CVE-2026-37719

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue in dormakaba evolo Service (all versions) allows a remote attacker to execute arbitrary code as SYSTEM via a .NET component.

Published 2026-10-05. Last modified 2026-10-06.